Right to delete
CCPA right to delete / CCPA deletion request / request to delete personal information
The CCPA right to delete lets a California consumer ask a covered business to erase personal information collected from them. Unless an exception applies, the business deletes it within 45 days, extendable once by 45 when reasonably necessary with notice. It also notifies service providers, contractors and, unless impossible or disproportionate, third parties it sold or shared data with.
A deletion request under California Civil Code section 1798.105 reaches past the business's own files. The business deletes the personal information from its records and notifies its service providers or contractors to delete it. It also notifies third parties it sold or shared the information with, unless this proves impossible or involves disproportionate effort.
At the business's direction, service providers and contractors delete the data or enable the business to delete it. They notify their own service providers or contractors. They also notify others who accessed the data through them, unless the business directed that access, or notice proves impossible or involves disproportionate effort. A vendor need not act on a deletion request a consumer sends it directly about data it handles for the business.
Under section 1798.130, a business must offer at least two ways to submit a request, including a toll-free number. An exclusively online business with a direct relationship with the consumer may use an email address instead. Separately, any business with a website must accept requests through it. No business may make someone create an account to ask, though it may send existing account holders through their account.
The California Privacy Protection Agency says a business must confirm receipt within 10 business days. It has 45 days from receipt to delete, and verification time counts against those days. It may extend once by 45 more days when reasonably necessary, with notice inside the first 45 days.
Section 1798.105 lists eight grounds for keeping data where reasonably necessary. They include completing the transaction, a written warranty or product recall, a good or service the consumer requested or would reasonably expect, and a contract. Others cover security, debugging, free speech or another legal right, the California Electronic Communications Privacy Act, expected internal uses, and a legal obligation. Consented research qualifies where deletion would seriously impair it.
The Attorney General's FAQ lists other common reasons and points to section 1798.145 for more. They include an unverifiable request, data needed to exercise or defend legal claims, and data exempt from the CCPA, such as publicly available information. A business may also keep a confidential record of deletion requests. The record may serve solely to keep the requester's information from being sold, to comply with laws, or for other purposes the CCPA permits.
In practice
A landscaping company covered by the CCPA gets a website deletion request from a past customer. It confirms receipt, verifies the person, and deletes the contact from its own customer list. It tells its email platform, call tracking vendor and other service providers holding the record to delete it. If an ad platform that counts as a third party received the list, it notifies that platform too. It keeps a confidential record of the request and any records a law requires, and responds within 45 calendar days.
Not the same as
- Right to opt-out of sale or sharing
- An opt-out stops a business from selling or sharing personal information after the request. A deletion request asks the business to erase information it collected. The business also notifies its service providers and contractors, and third parties it sold or shared the data with unless that proves impossible or involves disproportionate effort.
Why it matters to you
Customer details live in the email platform, quote software, call tracking and ad tools. A request handled only in the main inbox leaves copies the statute expects notices to reach. A policy without a toll-free number misses the rule unless the online-only exception applies.
What to ask or check
- 01Which request methods does your privacy policy list, including a toll-free number, and who watches them?
- 02Which vendors hold customer personal information, and is each a service provider, contractor or third party?
- 03How does the business verify a requester, and who tracks the 45-day deadline?
- 04Which records does the business keep after a deletion request, and which exception covers each one?
What people get wrong
That a deletion request reaches only the business's own records. California Civil Code 1798.105 requires the business to notify its service providers and contractors. It must also notify third parties it sold or shared the data with, unless that proves impossible or involves disproportionate effort.
Red flags
- A deletion request process that makes a person without an account create one first.
- A privacy policy that offers a web form as the only way to submit a request.
- No record of which vendors hold customer personal information on the business's behalf.